Platform Security

How we protect your business data

Zynopay implements security controls across data transmission, storage, access management, and application layer to protect customer and end-user data processed through our platform.

Security Controls

Our security framework

Data Transmission

  • TLS 1.2+ encryption on all data in transit
  • HTTPS enforced across all pages and APIs
  • HSTS headers enabled
  • Secure cookie attributes (HttpOnly, SameSite)

Data Storage

  • Database encryption at rest
  • Encrypted backups with retention controls
  • No payment card data stored on Zynopay servers
  • Data residency: India (AWS Mumbai region)

Access Control

  • Role-based access control (RBAC)
  • Least-privilege principle for all employees
  • Multi-factor authentication for admin access
  • Session timeout enforced

Application Security

  • Input validation and output encoding
  • SQL injection and XSS protections
  • CSRF token protection on all forms
  • Dependency scanning in CI/CD pipeline

Monitoring & Logging

  • Real-time anomaly detection on API traffic
  • Audit logs for all admin actions
  • Failed login attempt monitoring
  • 90-day log retention

Operational Security

  • Regular security reviews
  • Documented incident response process
  • Vendor security assessment for integrations
  • Business continuity plan maintained

We Never Store Payment Card Data

All payment card processing is handled by PCI-DSS compliant third-party payment gateways (Razorpay, PayU, Cashfree, etc.). Zynopay's servers never receive, process, or store raw card numbers, CVV codes, or full card details. This applies to payments made to Zynopay for subscriptions, and to transactions processed through the Zynopay platform by our customers.

Report a Security Issue

If you believe you've discovered a security vulnerability in Zynopay's platform or website, please report it responsibly to support@zynopay.in with subject line "Security Disclosure". We will acknowledge your report within 2 business days and work to resolve confirmed issues promptly. We request that you do not publicly disclose the issue until we have had reasonable time to address it.